Who was smart enough to implement rate limiting there, but not an exponential lockout period?
I have a password the maximum length allowed so it's not trivial to unlock when she does that.
I suspect most of these reports come from either bugs in the software (and some quick Googling suggests this has been the case), or perhaps that even someone (heck, even a savvy child) was trying using some sort of brute force exploit to unlock the phone.